SQL injection in Cacti - CVE-2019-17357

 

SQL injection in Cacti - CVE-2019-17357

Published: December 16, 2019


Vulnerability identifier: #VU23620
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17357
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.

The vulnerability exists due to insufficient sanitization of user-supplied data in graphs.php. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.

Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.


Affected software

Cacti
Gentoo Linux
Fedora
SUSE Linux
Opensuse
cacti (Debian package)
cacti
cacti-spine
SUSE Package Hub for SUSE Linux Enterprise

How to mitigate CVE-2019-17357

Install updates from vendor's website.

Cacti - update to 1.2.8
cacti (Debian package) - addressed in versions 0.8.8h+ds1-10+deb9u1, 1.2.2+ds1-2+deb10u2
cacti - addressed in versions 1.2.8-1.el7, 1.2.8-1.el8
cacti-spine - addressed in versions 1.2.8-1.el7, 1.2.8-1.el8

External References

Related Security Bulletins